FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
TT

FBI Warns US Companies about Iranian Hackers

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)
Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, said the FBI. (Getty Images)

Iranian hackers have searched cybercriminal websites for sensitive data stolen from American and foreign organizations that could be useful in future efforts to hack those organizations, the FBI said in an advisory sent to US companies obtained by CNN.

The Iranian hackers have taken an interest in dark-web forums, where scammers leak information on their victims such as stolen emails and network configurations, according to the November 8 advisory. The FBI is concerned that the Iranian hacking group could use that information to plot ways into US corporate networks in the future.

Organizations at risk are advised to take mitigation measures to block hacking attempts by securing Remote Desktop Protocol (RDP) servers, Web Application Firewalls, and Kentico CMS installations targeted by this adversary, said Bleeping Computer, a cybersecurity news outlet, which was the first to report on the FBI analysis.

"Among the Tactics, Techniques, and Procedures (TTPs) used in attacks by this threat actor since May 2021, the FBI mentions the use of auto-exploiter tools used to compromise WordPress sites to deploy web shells, breaching RDP servers and using them to maintain access to victims' networks."

It is unclear which Iranian hacking group is behind the activity. The FBI did not identify the hackers by name or say if they are linked to the Iranian government.

Adam Meyers, senior vice president of intelligence at security firm CrowdStrike, told CNN that Iranian government-linked hackers have increasingly dabbled in cybercriminal activity, such as ransomware, as a means of blurring the lines between state and non-state cyber operations.

"It is well within (Iranian groups') modus operandi to purchase access to networks held by a criminal group if it serves their interests," he added.

An unnamed Iranian hacking group used similar tools to steal voter registration data from state election sites between September and October 2020, Bleeping Computer.

"That voter info was later used to impersonate the far-right Proud Boys organization and send threatening emails to Democratic voters warning that they must vote for Trump or face the consequences."

"The FBI's Cyber Division also warned in a private industry notification issued last week that ransomware gangs have compromised the networks of several tribal-owned casinos, taking down their servers and disabling connected systems."

"The same week, the federal agency also alerted the public that criminals are increasingly using cryptocurrency ATMs and QR codes for fraud, making it harder for law enforcement to recover the victims' financial losses."



Iran Command Says Has Closed Hormuz Again over US Blockade

A satellite image shows the ship movement at the Strait of Hormuz on April 2, 2026, in Space. EUROPEAN UNION/COPERNICUS SENTINEL-2/Handout via REUTERS
A satellite image shows the ship movement at the Strait of Hormuz on April 2, 2026, in Space. EUROPEAN UNION/COPERNICUS SENTINEL-2/Handout via REUTERS
TT

Iran Command Says Has Closed Hormuz Again over US Blockade

A satellite image shows the ship movement at the Strait of Hormuz on April 2, 2026, in Space. EUROPEAN UNION/COPERNICUS SENTINEL-2/Handout via REUTERS
A satellite image shows the ship movement at the Strait of Hormuz on April 2, 2026, in Space. EUROPEAN UNION/COPERNICUS SENTINEL-2/Handout via REUTERS

Iran's central military command announced on Saturday it would resume "strict management" of the Strait of Hormuz, reversing a decision to unblock the strategic channel as part of negotiations with Washington.

In a statement shared on state television, the headquarters said Washington had broken a promise by continuing its naval blockade of ships sailing to and from Iran's ports.

Until the United States restores freedom of movement for all vessels visiting Iran, "the situation in the Strait of Hormuz will remain strictly controlled," the statement said.

The announcement came after US President Donald Trump said the blockade of the Strait will remain and attacks will resume if no agreement is reached with Iran.


Australia, Japan Sign Contracts to Start $7 Billion Warship Deal

Australia's Deputy Prime Minister and Minister for Defense Richard Marles (R) listens to Japan's Minister of Defense Koizumi Shinjiro (L) during a Defense Ministers' Meeting at the Commonwealth Parliament Offices in Melbourne on April 18, 2026. (Photo by William WEST / AFP)
Australia's Deputy Prime Minister and Minister for Defense Richard Marles (R) listens to Japan's Minister of Defense Koizumi Shinjiro (L) during a Defense Ministers' Meeting at the Commonwealth Parliament Offices in Melbourne on April 18, 2026. (Photo by William WEST / AFP)
TT

Australia, Japan Sign Contracts to Start $7 Billion Warship Deal

Australia's Deputy Prime Minister and Minister for Defense Richard Marles (R) listens to Japan's Minister of Defense Koizumi Shinjiro (L) during a Defense Ministers' Meeting at the Commonwealth Parliament Offices in Melbourne on April 18, 2026. (Photo by William WEST / AFP)
Australia's Deputy Prime Minister and Minister for Defense Richard Marles (R) listens to Japan's Minister of Defense Koizumi Shinjiro (L) during a Defense Ministers' Meeting at the Commonwealth Parliament Offices in Melbourne on April 18, 2026. (Photo by William WEST / AFP)

Australia and Japan signed contracts on Saturday launching their landmark A$10 billion ($7 billion) deal to supply Australia with warships, Tokyo's most consequential military sale since ending a military export ban in 2014.

Defense Ministers Richard Marles and Shinjiro Koizumi signed a memorandum "reaffirming the Australian and Japanese governments' shared commitment to the successful delivery" of the warships, Marles said in a statement.

The deal struck in ⁠August anchors Japan's ⁠push away from its postwar pacifism to forge security ties beyond its alliance with the US to counter China.

Mitsubishi Heavy Industries is to supply the Royal Australian Navy with three upgraded Mogami-class ⁠multi-role frigates built in Japan from 2029. Eight more frigates will be built in Australia.

Japan's Defense Ministry posted on X that Koizumi and Marles welcomed the "conclusion of contracts for General Purpose Frigates, and confirmed to further strengthen bilateral defense ties" in the signing in Melbourne.

Contracts were signed for the first three frigates, to be built ⁠in ⁠Japan, before there is a "transition to an onshore build" at the Henderson shipyard near Perth in Western Australia, Reuters quoted Marles as saying.

Australia plans to deploy the ships - designed to hunt submarines, strike surface ships and provide air defense - to defend critical maritime trade routes and its northern approaches in the Indian and Pacific Oceans, where China's military footprint is expanding.


Iran Partially Reopens Airspace

FILE - Two police officers walk in front of an anti-US billboard in Tehran, Iran, Sunday, April 5, 2026. (AP Photo/Vahid Salemi, File)
FILE - Two police officers walk in front of an anti-US billboard in Tehran, Iran, Sunday, April 5, 2026. (AP Photo/Vahid Salemi, File)
TT

Iran Partially Reopens Airspace

FILE - Two police officers walk in front of an anti-US billboard in Tehran, Iran, Sunday, April 5, 2026. (AP Photo/Vahid Salemi, File)
FILE - Two police officers walk in front of an anti-US billboard in Tehran, Iran, Sunday, April 5, 2026. (AP Photo/Vahid Salemi, File)

Iran partially reopened its airspace on Saturday to international flights crossing the eastern part of its territory, the country's Civil Aviation Authority said.

"Air routes in the eastern section of the country's airspace are open for international flights transiting through Iran," it said, adding that some airports had also reopened at 7:00 am (0330 GMT).

More than three hours later, however, flight tracker websites still showed no international flights crossing Iran, and several avoiding its airspace by making long detours.